Code Injection in Spring Cloud Function - CVE-2022-22963
Published: March 31, 2022 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation within the routing functionality when processing SpEL expressions. A remote attacker can send a specially crafted HTTP request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Oracle Banking Liquidity Management
Oracle Banking Credit Facilities Process Management
Oracle Banking Branch
Oracle Banking Cash Management
Oracle Banking Corporate Lending Process Management
Oracle Banking Electronic Data Exchange for Corporates
Oracle Banking Origination
Oracle Banking Supply Chain Finance
Oracle Banking Trade Finance Process Management
Oracle Banking Virtual Account Management
Red Hat OpenShift Serverless
Red Hat Advanced Cluster Security for Kubernetes
FortiSOAR
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Oracle Communications Cloud Native Core Policy
openshift-serverless-clients (Red Hat package)
OpenShift Serverless Client
Dell EMC VxRail Appliance
How to mitigate CVE-2022-22963
Red Hat OpenShift Serverless - update to 1.21.1
Red Hat Advanced Cluster Security for Kubernetes - update to 3.70
FortiSOAR - update to 7.2.0
openshift-serverless-clients (Red Hat package) - update to 1.0.1-2.el8
OpenShift Serverless Client - update to 1.21.1
Dell EMC VxRail Appliance - update to 4.5.480
Links to Public Exploits and PoC-codes
- Exploit #10747 - Spring Cloud 3.2.2 - Remote Command Execution (RCE) (October 25, 2024)
- Exploit #9178 - CVE-Exploits (CVE-POC) (July 10, 2023)
- Exploit #9164 - Exploit-for-CVE-2022-22963 (An exploit for the CVE-2022-22963 (Spring Cloud Function Vulnerability)) (June 29, 2023)
- Exploit #8984 - CVE-2022-22963-Exploit (Rust-based exploit for the CVE-2022-22963 vulnerability) (April 14, 2023)
- Exploit #8939 - CVE-2022-22963-PoC (CVE-2022-22963 RCE PoC in python) (March 28, 2023)
- Exploit #8925 - CVE-2022-22963_Reverse-Shell-Exploit (CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify if the vulnerability exists, and if it does, will give you a reverse (March 20, 2023)
- Exploit #8908 - CVE-2022-22963 (spring cloud function 一键利用工具! by charis 博客https://charis3306.top/) (March 13, 2023)
- Exploit #8742 - CVE-2022-22963-POC () (January 16, 2023)
- Exploit #7879 - CVE-2022-22963 () (May 23, 2022)
- Exploit #7776 - Spring Cloud Function SpEL Injection (May 12, 2022)
- Exploit #7652 - spring-cloud-function-rce (Spring Cloud Function SPEL表达式注入漏洞(CVE-2022-22963)) (April 15, 2022)
- Exploit #7643 - spring-spel-0day-poc (spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963) (April 14, 2022)
- Exploit #7604 - SpringCloudFunction-Research (CVE-2022-22963 research) (April 5, 2022)
- Exploit #7583 - CVE-2022-22963 (Spring Cloud Function Vulnerable Application / CVE-2022-22963) (April 3, 2022)
- Exploit #7572 - CVE-2022-22963 () (April 1, 2022)
- Exploit #7571 - CVE-2022-22963-Spring-Core-RCE (A Proof-of-Concept (PoC) of the Spring Core RCE (Spring4Shell or CVE-2022-22963) in Bash (Linux).) (April 1, 2022)
- Exploit #7570 - CVE-2022-22965 (Vulnerabilidad RCE en Spring Framework vía Data Binding on JDK 9+ (CVE-2022-22965 aka "Spring4Shell")) (March 31, 2022)
- Exploit #7566 - Spring-CVE (This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed "SpringShell".) (March 31, 2022)
- Exploit #7564 - CVE-2022-22963 (CVE-2022-22963 PoC ) (March 31, 2022)
- Exploit #7559 - CVE-2022-22963 () (March 31, 2022)
- Exploit #7558 - SpringShell (Spring4Shell - Spring Core RCE - CVE-2022-22965) (March 31, 2022)
- Exploit #7557 - Spring0DayCoreExploit ({ Spring Core 0day CVE-2022-22963 }) (March 31, 2022)
- Exploit #7556 - CVE-2022-22963-PoC () (March 31, 2022)
External References
Related Security Bulletins
- Remote code execution in Spring Cloud Function
- Remote code execution in OpenShift Serverless
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Function Cloud Native Environment
- Code Injection in Oracle Banking Virtual Account Management
- Code Injection in Oracle Banking Trade Finance Process Management
- Code Injection in Oracle Banking Supply Chain Finance
- Code Injection in Oracle Banking Origination
- Code Injection in Oracle Banking Liquidity Management
- Code Injection in Oracle Banking Electronic Data Exchange for Corporates
- Code Injection in Oracle Banking Credit Facilities Process Management
- Code Injection in Oracle Banking Corporate Lending Process Management
- Code Injection in Oracle Banking Cash Management
- Code Injection in Oracle Banking Branch
- Multiple vulnerabilities in Dell VxRail
- FortiSOAR update for Spring4Shell vulnerabilities
- Code Injection in OpenShift Serverless Client 1.21